Enterprise Cisco Lab & Infrastructure Engineering
Scope: Multi-VLAN Architecture, OSPF Dynamic Routing, Trunking & Infrastructure Security
Project Overview
Designed, configured, and validated a multi-tier enterprise network topology utilizing Cisco routers and Layer 2/Layer 3 switches. The lab environment simulates a scalable branch-to-core infrastructure featuring segmented departmental VLANs, resilient inter-VLAN routing, dynamic OSPF routing, and hardened network edge security.
Cisco Lab Topology & Source Architecture
Cisco Packet Tracer Multi-VLAN & OSPF Lab Model
Core Network Architecture & Implementation
VLAN Segmentation & Trunking
Configured departmental VLANs (Management, Data, VoIP, and Guest) on Layer 2 switches. Implemented 802.1Q trunking with custom Native VLAN mapping and active DTP disabling for security.
Inter-VLAN Routing & L3 Switching
Deployed Router-on-a-Stick (ROAS) sub-interfaces on Cisco routers and configured Switched Virtual Interfaces (SVIs) on Layer 3 switches for high-throughput inter-departmental packet routing.
OSPF Dynamic Routing
Implemented Single-Area OSPF (Area 0) across core routers. Configured passive interfaces to prevent unauthorized routing updates on client-facing subnets and calibrated link metrics.
Security Hardening & NAT
Configured Port Security (Sticky MAC limits), SSH access (RSA 2048-bit keys), Access Control Lists (Extended ACLs), and Dynamic NAT/PAT for secure edge internet gateway connectivity.
Infrastructure Operations & Verification Protocols
Dynamic Adjacency Validation
Monitored link-state database updates and verified peer neighbor states across core nodes to maintain route convergence and low-latency failover resilience.
Traffic Segmentation Auditing
Audited 802.1Q encapsulation frames and trunk connection health to ensure strict logical isolation across administrative and operational subnets.
Edge Access Safeguards
Enforced encrypted remote access protocols, restricted management console permissions, and applied interface-level MAC security controls.